Compare commits

...
40 Commits
Author SHA1 Message Date
Marcus Young 12755b572f [Automated 🤖 ] Bump to version 2.284.0 2021-11-01 10:37:01 -05:00
Marcus Young e4b56c3d76 [Automated 🤖 ] Bump to version 2.283.3 2021-10-04 14:14:55 -05:00
Marcus Young b91ff43474 [Automated 🤖 ] Bump to version 2.283.2 2021-09-30 08:04:43 -05:00
myoung34andGitHub 3e5e6de819 Merge pull request #150 from gazab/patch-1
Fix small typo in entrypoint.sh log output
2021-09-22 07:30:19 -05:00
Gustav TonérandGitHub d0da2268ee Fix typo in entrypoint.sh log output 2021-09-22 13:24:20 +02:00
Marcus Young fbc204bc10 [Automated 🤖 ] Bump to version 2.283.1 2021-09-20 09:06:26 -05:00
Marcus Young 162cb1f201 [Automated 🤖 ] Bump to version 2.283.0 2021-09-20 08:21:05 -05:00
Marcus Young 0e38dc10ce [Automated 🤖 ] Bump to version 2.282.1 2021-09-15 13:04:58 -05:00
myoung34andGitHub dd77bee9a9 Merge pull request #149 from myoung34/signals
Fix deregistration hijacking
2021-09-15 10:26:18 -05:00
Marcus Young c837c99a7b Fix deregistration hijacking 2021-09-15 10:23:46 -05:00
myoung34andGitHub 10b21dfc71 Merge pull request #141 from joeyparrish/deregistration
Fix runner deregistration with ACCESS_TOKEN
2021-09-15 10:22:25 -05:00
myoung34andGitHub e386012396 Merge branch 'master' into deregistration 2021-09-15 08:31:07 -05:00
myoung34andGitHub 4df911ff4b Merge pull request #145 from Niek/master
Fix #142 - building on Sid
2021-09-15 08:29:28 -05:00
myoung34andGitHub d75627b94e Merge pull request #143 from JulianGro/update_debian
Update Debian README information
2021-09-15 08:19:45 -05:00
myoung34andGitHub 2aa12337bb Merge pull request #146 from JulianGro/fix_locale
Properly enable locale
2021-09-15 08:19:12 -05:00
myoung34andGitHub 37ffbfad94 Merge pull request #147 from lukaszjankowski/fix-typo
Fix typo in entrypoint.sh
2021-09-15 08:17:53 -05:00
Łukasz JankowskiandGitHub 9bf27c4aac Update entrypoint.sh 2021-09-14 11:20:43 +02:00
Julian Groß 3cbb4714a8 Properly enable locale 2021-09-13 23:58:46 +02:00
Marcus Young 85d2ef126b [Automated 🤖 ] Bump to version 2.282.0 2021-09-13 13:17:21 -05:00
Niek van der MaasandGitHub c9b0931b5a Merge branch 'myoung34:master' into master 2021-09-13 12:35:32 +02:00
Niek van der Maas 450ab99ee9 Fix Sid support 2021-09-13 12:35:12 +02:00
Julian Groß 4006da573c Update Debian README as Debian Bullseye has been released as stable. 2021-09-11 03:35:30 +02:00
myoung34andGitHub b11f137e68 Merge pull request #140 from joeyparrish/ephemeral
feat: Ephemeral mode
2021-09-10 11:17:06 -05:00
53089f4326 Accept maintainer's suggestion in README
Co-authored-by: myoung34 <myoung34@my.apsu.edu>
2021-09-10 12:16:06 -04:00
Joey Parrish 844d91507d Add docs for ephemeral mode 2021-09-10 09:08:35 -07:00
Joey Parrish 816a1c181f Fix runner deregistration with ACCESS_TOKEN
This fixes runner deregistration, which needs to have ACCESS_TOKEN still
defined to fetch a fresh RUNNER_TOKEN for deregistration.

The original purpose of unsetting the variables would seem to be for
security, to make sure they unavailable to the jobs running in the
container. Unexporting the variables achieves the same goal, but leaves
them available to the entrypoint later when it runs the deregistration
process.
2021-09-10 08:56:00 -07:00
Joey Parrish ced39230ac feat: Ephemeral mode 2021-09-10 08:49:45 -07:00
Marcus Young fdd8a7d93a [Automated 🤖 ] Bump to version 2.281.1 2021-09-01 15:34:45 -05:00
Marcus Young 745904194f [Automated 🤖 ] Bump to version 2.281.0 2021-08-30 12:32:46 -05:00
Marcus Young 37adeae591 [Automated 🤖 ] Bump to version 2.280.3 2021-08-19 08:26:40 -05:00
Marcus Young f87f07f8f9 [Automated 🤖 ] Bump to version 2.280.2 2021-08-12 12:44:46 -05:00
myoung34andGitHub 9ed686442d Merge pull request #134 from joeyparrish/install-python2
Make python2 the default python version
2021-08-04 15:39:01 -05:00
Joey Parrish 20e2344ae0 Make python2 the default python version
It turns out that the "python2" package in Ubuntu doesn't touch
/usr/bin/python.  To get /usr/bin/python pointing to /usr/bin/python2,
you are supposed to install the "python" package.  I didn't realize this
when I made PR #132, and I didn't test thoroughly enough with my own
workflows to realize my mistake.

This corrects the package name to "python", making python2 the default.
2021-08-04 13:34:39 -07:00
Marcus Young 2991edd770 [Automated 🤖 ] Bump to version 2.280.1 2021-08-04 12:40:12 -05:00
myoung34andGitHub 70cfc22566 Merge pull request #133 from joeyparrish/fix-chmod
Fix failing chmod on docker-compose on arm
2021-08-04 11:33:42 -05:00
myoung34andGitHub 00824687a7 Merge pull request #132 from joeyparrish/install-python2
Add python2 to base image
2021-08-04 11:31:14 -05:00
Joey Parrish 746ef939c5 Fix failing chmod on docker-compose on arm
Since docker-compose is not downloaded on arm, the chmod command fails
there.  Moving it inside the previous command, after curl, ensures it
only runs when it should.
2021-08-04 09:31:05 -07:00
Joey Parrish 30ff3b9560 Add python2 to base image
Since GitHub Actions environments include python2, this improves
compatibility for the docker image.
2021-08-04 08:55:21 -07:00
myoung34andGitHub 69daab6ad2 Merge pull request #127 from joeyparrish/comment-git-source-build
Add a comment about why git is built from source
2021-08-03 16:42:30 -05:00
Joey Parrish e60f5986bb Add a comment about why git is built from source
Closes #125
2021-08-03 14:39:46 -07:00
5 changed files with 127 additions and 25 deletions
+4 -4
View File
@@ -5,7 +5,7 @@ LABEL maintainer="myoung34@my.apsu.edu"
ENV AGENT_TOOLSDIRECTORY=/opt/hostedtoolcache
RUN mkdir -p /opt/hostedtoolcache
ARG GH_RUNNER_VERSION="2.280.0"
ARG GH_RUNNER_VERSION="2.284.0"
ARG TARGETPLATFORM
SHELL ["/bin/bash", "-o", "pipefail", "-c"]
@@ -17,8 +17,8 @@ RUN chmod +x /actions-runner/install_actions.sh \
&& /actions-runner/install_actions.sh ${GH_RUNNER_VERSION} ${TARGETPLATFORM} \
&& rm /actions-runner/install_actions.sh
COPY token.sh entrypoint.sh /
RUN chmod +x /token.sh /entrypoint.sh
COPY token.sh entrypoint.sh ephemeral-runner.sh /
RUN chmod +x /token.sh /entrypoint.sh /ephemeral-runner.sh
ENTRYPOINT ["/entrypoint.sh"]
CMD ["/actions-runner/bin/runsvc.sh"]
CMD ["./bin/Runner.Listener", "run", "--startuptype", "service"]
+19 -10
View File
@@ -1,19 +1,25 @@
FROM ubuntu:focal
LABEL maintainer="myoung34@my.apsu.edu"
# TODO: Ubuntu focal (20.04) has git v2.25, but the minimum needed for GitHub
# Actions runners is v2.29. For now, we build git from source. When updating
# to hirsute (21.04) or later, we can remove the instructions to build from
# source in favor of the regular Ubuntu git package.
ARG GIT_VERSION="2.29.0"
ARG DUMB_INIT_VERSION="1.2.2"
ARG DOCKER_KEY="7EA0A9C3F273FCD8"
ENV DOCKER_COMPOSE_VERSION="1.27.4"
ENV LANG=en_US.UTF-8
ENV LANGUAGE=en_US:en
ENV LC_ALL=en_US.UTF-8
ENV LANGUAGE=en_US.UTF-8
ENV LC_ALL=en_US.UTF-8
SHELL ["/bin/bash", "-o", "pipefail", "-c"]
ENV DEBIAN_FRONTEND=noninteractive
# hadolint ignore=DL3003,DL4001
RUN apt-get update && \
apt-get install -y --no-install-recommends \
RUN echo en_US.UTF-8 UTF-8 >> /etc/locale.gen \
&& apt-get update \
&& apt-get install -y --no-install-recommends \
awscli \
curl \
tar \
@@ -37,10 +43,9 @@ RUN apt-get update && \
openssh-client \
locales \
python3-pip \
python \
dumb-init \
&& pip3 install --no-cache-dir awscliv2 \
&& locale-gen en_US.UTF-8 \
&& dpkg-reconfigure locales \
&& c_rehash \
&& cd /tmp \
&& curl -sL https://www.kernel.org/pub/software/scm/git/git-${GIT_VERSION}.tar.gz -o git.tgz \
@@ -50,12 +55,16 @@ RUN apt-get update && \
&& make \
&& make install \
&& cd / \
# Determine the Distro name (Debian, Ubuntu, etc)
&& distro=$(lsb_release -is | awk '{print tolower($0)}') \
# Determine the Distro version (bullseye, xenial, etc)
# Note: sid is aliased to bullseye, because Docker doesn't have a matching apt repo
&& apt-key adv --keyserver keyserver.ubuntu.com --recv-keys ${DOCKER_KEY} \
&& curl -fsSL https://download.docker.com/linux/$(lsb_release -is | awk '{print tolower($0)}')/gpg | apt-key add - \
&& ( add-apt-repository "deb [arch=$(dpkg --print-architecture)] https://download.docker.com/linux/$(lsb_release -is | awk '{print tolower($0)}') $(lsb_release -cs) stable" ) \
&& curl -fsSL https://download.docker.com/linux/${distro}/gpg | apt-key add - \
&& version=$(lsb_release -cs | awk '{gsub("sid", "bullseye"); print $0}') \
&& ( add-apt-repository "deb [arch=$(dpkg --print-architecture)] https://download.docker.com/linux/${distro} ${version} stable" ) \
&& apt-get update \
&& apt-get install -y docker-ce docker-ce-cli containerd.io --no-install-recommends --allow-unauthenticated \
&& [[ $(lscpu -J | jq -r '.lscpu[] | select(.field == "Vendor ID:") | .data') == "ARM" ]] && echo "Not installing docker-compose. See https://github.com/docker/compose/issues/6831" || ( curl -sL "https://github.com/docker/compose/releases/download/${DOCKER_COMPOSE_VERSION}/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose ) \
&& chmod +x /usr/local/bin/docker-compose \
&& [[ $(lscpu -J | jq -r '.lscpu[] | select(.field == "Vendor ID:") | .data') == "ARM" ]] && echo "Not installing docker-compose. See https://github.com/docker/compose/issues/6831" || ( curl -sL "https://github.com/docker/compose/releases/download/${DOCKER_COMPOSE_VERSION}/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose && chmod +x /usr/local/bin/docker-compose ) \
&& rm -rf /var/lib/apt/lists/* \
&& rm -rf /tmp/*
+56 -3
View File
@@ -28,9 +28,9 @@ A workaround exists, please see [here](https://github.com/myoung34/docker-github
| --- | --- | --- | --- | --- | --- |
| ubuntu focal | `x86_64`,`arm64` | `/\d\.\d{3}\.\d+/` | [latest](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=latest) | This is the latest build (Rebuilt nightly and on master merges). Tags without an OS name are included. | Tags without an OS name *before* 9/17/2020 are `eoan`. `armv7` support stopped 9/18/2020 due to inconsistent docker-ce packaging |
| ubuntu bionic | `x86_64`,`armv7`,`arm64` | `/\d\.\d{3}\.\d+-ubuntu-bionic/` | [ubuntu-bionic](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=ubuntu-bionic) | This is the latest build from bionic (Rebuilt nightly and on master merges). Tags with `-ubuntu-bionic` are included and created on [upstream tags](https://github.com/actions/runner/tags). | |
| debian buster | `x86_64`,`arm64`,`armv7` | `/\d\.\d{3}\.\d+-debian-buster/` | [debian-buster](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=debian-buster) | This is the latest build from buster (Rebuilt nightly and on master merges). Tags with `-debian-buster` are included and created on [upstream tags](https://github.com/actions/runner/tags). | |
| debian bullseye | `x86_64`,`arm64`,`armv7` | `/\d\.\d{3}\.\d+-debian-bullseye/` | [debian-bullseye](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=debian-bullseye) | This is the latest build from bullseye (Rebuilt nightly and on master merges). Tags with `-debian-bullseye` are included and created on [upstream tags](https://github.com/actions/runner/tags). | Debian Bullseye will be the next stable release of Debian Linux. |
| debian sid | `x86_64`,`arm64`,`admv7` | `/\d\.\d{3}\.\d+-debian-sid/` | [debian-sid](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=debian-sid) | This is the latest build from sid (Rebuilt nightly and on master merges). Tags with `-debian-sid` are included and created on [upstream tags](https://github.com/actions/runner/tags). | Debian sid is considered unstable by Debian. |
| debian buster | `x86_64`,`arm64`,`armv7` | `/\d\.\d{3}\.\d+-debian-buster/` | [debian-buster](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=debian-buster) | This is the latest build from buster (Rebuilt nightly and on master merges). Tags with `-debian-buster` are included and created on [upstream tags](https://github.com/actions/runner/tags). | Buster is Debians current old-stable release. |
| debian bullseye | `x86_64`,`arm64`,`armv7` | `/\d\.\d{3}\.\d+-debian-bullseye/` | [debian-bullseye](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=debian-bullseye) | This is the latest build from bullseye (Rebuilt nightly and on master merges). Tags with `-debian-bullseye` are included and created on [upstream tags](https://github.com/actions/runner/tags). | Bullseye is Debians current stable release. |
| debian sid | `x86_64`,`arm64`,`admv7` | `/\d\.\d{3}\.\d+-debian-sid/` | [debian-sid](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=debian-sid) | This is the latest build from sid (Rebuilt nightly and on master merges). Tags with `-debian-sid` are included and created on [upstream tags](https://github.com/actions/runner/tags). | Sid is considered unstable by Debian. |
| ubuntu xenial | `x86_64`,`arm64` | `/\d\.\d{3}\.\d+-ubuntu-xenial/` | [ubuntu-xenial](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=ubuntu-xenial) | This is the latest build from xenial (Rebuilt nightly and on master merges). Tags with `-ubuntu-xenial` are included and created on [upstream tags](https://github.com/actions/runner/tags). | This is deprecated as of 7/15/2021 and will no longer receive tags. |
These containers are built via Github actions that [copy the dockerfile](https://github.com/myoung34/docker-github-actions-runner/blob/master/.github/workflows/deploy.yml#L47), changing the `FROM` and building to provide simplicity.
@@ -315,3 +315,56 @@ docker run -d --restart always --name github-runner \
-v /tmp/github-runner-your-repo:/tmp/github-runner-your-repo \
myoung34/github-runner:latest
```
## Ephemeral mode
GitHub's hosted runners are completely ephemeral. You can remove all its data without breaking all future jobs.
To achieve the same resilience in a self-hosted runner:
1. override the command for your runner with `/ephemeral-runner.sh` (which will terminate after one job executes)
2. don't mount a local folder into `RUNNER_WORKDIR` (to ensure no filesystem persistence)
3. run the container with `--rm` (to delete it after termination)
4. wrap the container execution in a system service that restarts (to start a fresh container after each job)
Here's an example service definition for systemd:
```
# Install with:
# sudo install -m 644 ephemeral-github-actions-runner.service /etc/systemd/system/
# sudo systemctl daemon-reload
# sudo systemctl enable ephemeral-github-actions-runner
# Run with:
# sudo systemctl start ephemeral-github-actions-runner
# Stop with:
# sudo systemctl stop ephemeral-github-actions-runner
# See live logs with:
# journalctl -f -u ephemeral-github-actions-runner.service --no-hostname --no-tail
[Unit]
Description=Ephemeral GitHub Actions Runner Container
After=docker.service
Requires=docker.service
[Service]
TimeoutStartSec=0
Restart=always
ExecStartPre=-/usr/bin/docker stop %n
ExecStartPre=-/usr/bin/docker rm %n
ExecStartPre=-/usr/bin/docker pull myoung34/github-runner:latest
ExecStart=/usr/bin/docker run --rm --env-file /etc/ephemeral-github-actions-runner.env --name %n myoung34/ephemeral-github-actions-runner:latest /ephemeral-runner.sh
[Install]
WantedBy=multi-user.target
```
And an example of the corresponding env file that the service reads from:
```
# Install with:
# sudo install -m 600 ephemeral-github-actions-runner.env /etc/
REPO_URL=https://github.com/your-org/your-repo
RUNNER_NAME=your-runner-name-here
ACCESS_TOKEN=foo-access-token
RUNNER_WORKDIR=/tmp/runner/work
LABELS=any-custom-labels-go-here
```
+12 -8
View File
@@ -3,10 +3,17 @@
export RUNNER_ALLOW_RUNASROOT=1
export PATH=$PATH:/actions-runner
# Un-export these, so that they must be passed explicitly to the environment of
# any command that needs them. This may help prevent leaks.
export -n ACCESS_TOKEN
export -n RUNNER_TOKEN
deregister_runner() {
echo "Caught SIGTERM. Deregistering runner"
_TOKEN=$(bash /token.sh)
RUNNER_TOKEN=$(echo "${_TOKEN}" | jq -r .token)
if [[ -n "${ACCESS_TOKEN}" ]]; then
_TOKEN=$(ACCESS_TOKEN="${ACCESS_TOKEN}" bash /token.sh)
RUNNER_TOKEN=$(echo "${_TOKEN}" | jq -r .token)
fi
./config.sh remove --token "${RUNNER_TOKEN}"
exit
}
@@ -53,8 +60,8 @@ esac
configure_runner() {
if [[ -n "${ACCESS_TOKEN}" ]]; then
echo "Obtaining the token of the runnet"
_TOKEN=$(bash /token.sh)
echo "Obtaining the token of the runner"
_TOKEN=$(ACCESS_TOKEN="${ACCESS_TOKEN}" bash /token.sh)
RUNNER_TOKEN=$(echo "${_TOKEN}" | jq -r .token)
fi
@@ -98,11 +105,8 @@ if [[ -n "${CONFIGURED_ACTIONS_RUNNER_FILES_DIR}" ]]; then
fi
if [[ ${_DISABLE_AUTOMATIC_DEREGISTRATION} == "false" ]]; then
trap deregister_runner SIGINT SIGQUIT SIGTERM
trap deregister_runner SIGINT SIGQUIT SIGTERM INT TERM QUIT
fi
unset ACCESS_TOKEN
unset RUNNER_TOKEN
# Container's command (CMD) execution
"$@"
+36
View File
@@ -0,0 +1,36 @@
#!/bin/bash
echo "*** Starting ephemeral runner. ***"
/actions-runner/run.sh --once
rv=$?
# See exit code constants in the runner source here:
# https://github.com/actions/runner/blob/be96323/src/Runner.Common/Constants.cs#L135
if [[ $rv == 4 ]]; then
# The runner software was updated.
echo "*** Software update detected. ***"
echo "*** Waiting for update to complete. ***"
# Hard-coded sleep. Without some delay, the update is still in progress in
# the background, leading to failures when we re-launch.
sleep 10
# Now add an adaptive delay, where we loop and check if the Runner is usable
# yet. As soon as it is, break.
for i in $(seq 10); do
if /actions-runner/bin/Runner.Listener --version &>/dev/null; then
break
fi
echo "*** Update still in progress... ***"
sleep 5
done
# Now re-launch the script.
echo "*** Re-launching runner. ***"
exec "$0"
fi
# For any other return value, let the script and the Docker container terminate.
echo "*** Exit code $rv ***"
exit $rv